Impact
A vulnerability exists in the Oracle JDeveloper product’s Security Framework that permits a low‑privileged attacker with network access to the HTTP interface to compromise the application. Upon successful exploitation, the attacker can take full control of Oracle JDeveloper, compromising confidentiality, integrity, and availability of the system. The CVSS score of 8.8 reflects a high severity impact of this flaw.
Affected Systems
The flaw affects Oracle Corporation’s JDeveloper product. Supported versions impacted are 12.2.1.4.0 and 14.1.2.0.0. Users running these releases should verify whether they are still supported and seek corresponding fixes from Oracle.
Risk and Exploitability
The CVSS base score is 8.8 and the EPSS score is below 1 %, indicating a technically high‑impact vulnerability that is unlikely to be widely exploited yet remains a serious threat. It is not listed in CISA’s KEV catalog. The likely attack vector is a network‑based HTTP connection to the JDeveloper instance, requiring only a low‑privilege user. Successful exploitation would lead to full application takeover.
OpenCVE Enrichment